|
5 | 5 | package ssh
|
6 | 6 |
|
7 | 7 | import (
|
| 8 | + "io" |
| 9 | + "net" |
| 10 | + "sync/atomic" |
8 | 11 | "testing"
|
| 12 | + "time" |
9 | 13 | )
|
10 | 14 |
|
11 | 15 | func TestClientAuthRestrictedPublicKeyAlgos(t *testing.T) {
|
@@ -59,27 +63,78 @@ func TestClientAuthRestrictedPublicKeyAlgos(t *testing.T) {
|
59 | 63 | }
|
60 | 64 |
|
61 | 65 | func TestNewServerConnValidationErrors(t *testing.T) {
|
62 |
| - c1, c2, err := netPipe() |
63 |
| - if err != nil { |
64 |
| - t.Fatalf("netPipe: %v", err) |
65 |
| - } |
66 |
| - defer c1.Close() |
67 |
| - defer c2.Close() |
68 |
| - |
69 | 66 | serverConf := &ServerConfig{
|
70 | 67 | PublicKeyAuthAlgorithms: []string{CertAlgoRSAv01},
|
71 | 68 | }
|
72 |
| - _, _, _, err = NewServerConn(c1, serverConf) |
| 69 | + c := &markerConn{} |
| 70 | + _, _, _, err := NewServerConn(c, serverConf) |
73 | 71 | if err == nil {
|
74 | 72 | t.Fatal("NewServerConn with invalid public key auth algorithms succeeded")
|
75 | 73 | }
|
| 74 | + if !c.isClosed() { |
| 75 | + t.Fatal("NewServerConn with invalid public key auth algorithms left connection open") |
| 76 | + } |
| 77 | + if c.isUsed() { |
| 78 | + t.Fatal("NewServerConn with invalid public key auth algorithms used connection") |
| 79 | + } |
| 80 | + |
76 | 81 | serverConf = &ServerConfig{
|
77 | 82 | Config: Config{
|
78 | 83 | KeyExchanges: []string{kexAlgoDHGEXSHA256},
|
79 | 84 | },
|
80 | 85 | }
|
81 |
| - _, _, _, err = NewServerConn(c1, serverConf) |
| 86 | + c = &markerConn{} |
| 87 | + _, _, _, err = NewServerConn(c, serverConf) |
82 | 88 | if err == nil {
|
83 | 89 | t.Fatal("NewServerConn with unsupported key exchange succeeded")
|
84 | 90 | }
|
| 91 | + if !c.isClosed() { |
| 92 | + t.Fatal("NewServerConn with unsupported key exchange left connection open") |
| 93 | + } |
| 94 | + if c.isUsed() { |
| 95 | + t.Fatal("NewServerConn with unsupported key exchange used connection") |
| 96 | + } |
| 97 | +} |
| 98 | + |
| 99 | +type markerConn struct { |
| 100 | + closed uint32 |
| 101 | + used uint32 |
85 | 102 | }
|
| 103 | + |
| 104 | +func (c *markerConn) isClosed() bool { |
| 105 | + return atomic.LoadUint32(&c.closed) != 0 |
| 106 | +} |
| 107 | + |
| 108 | +func (c *markerConn) isUsed() bool { |
| 109 | + return atomic.LoadUint32(&c.used) != 0 |
| 110 | +} |
| 111 | + |
| 112 | +func (c *markerConn) Close() error { |
| 113 | + atomic.StoreUint32(&c.closed, 1) |
| 114 | + return nil |
| 115 | +} |
| 116 | + |
| 117 | +func (c *markerConn) Read(b []byte) (n int, err error) { |
| 118 | + atomic.StoreUint32(&c.used, 1) |
| 119 | + if atomic.LoadUint32(&c.closed) != 0 { |
| 120 | + return 0, net.ErrClosed |
| 121 | + } else { |
| 122 | + return 0, io.EOF |
| 123 | + } |
| 124 | +} |
| 125 | + |
| 126 | +func (c *markerConn) Write(b []byte) (n int, err error) { |
| 127 | + atomic.StoreUint32(&c.used, 1) |
| 128 | + if atomic.LoadUint32(&c.closed) != 0 { |
| 129 | + return 0, net.ErrClosed |
| 130 | + } else { |
| 131 | + return 0, io.ErrClosedPipe |
| 132 | + } |
| 133 | +} |
| 134 | + |
| 135 | +func (*markerConn) LocalAddr() net.Addr { return nil } |
| 136 | +func (*markerConn) RemoteAddr() net.Addr { return nil } |
| 137 | + |
| 138 | +func (*markerConn) SetDeadline(t time.Time) error { return nil } |
| 139 | +func (*markerConn) SetReadDeadline(t time.Time) error { return nil } |
| 140 | +func (*markerConn) SetWriteDeadline(t time.Time) error { return nil } |
0 commit comments